Podlipodcast player Webplayer

DISCARDED: Tales From the Threat Research Trenches

DISCARDED: Tales From the Threat Research Trenches

TrustConnect RAT: Inside a Vibe-Coded Malware Ecosystem

DISCARDED: Tales From the Threat Research Trenches · Mar 10, 2026 · 42:48

0:0042:48

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

Send us fan mail!

Hello to all our Cyber Pals! Host Selena Larson and co-host, Tim Kromphardt, chat with Tommy Madjar, Senior Threat Researcher from Proofpoint, to unpack one of the strangest malware investigations of the year: TrustConnect RAT.

What started as a seemingly legitimate remote management tool quickly unraveled into a bizarre, fast-evolving ecosystem of “vibe-coded” malware. TrustConnect masqueraded as a polished RMM platform—complete with fake testimonials, inflated customer counts, and even an extended validation (EV) code-signing certificate to appear trustworthy. But beneath the surface? Sloppy AI-generated web panels, exposed administrative pages, and a backend that literally labeled infected machines as “victims.”

Tommy walks through how the team discovered the malware, why attackers are increasingly building their own fake RMM platforms instead of abusing legitimate ones, and how the use of EV certificates helped the malware evade detection across security tools. 

The conversation also dives into:


Along the way, the team explores a broader theme: what happens when threat actors move fast with AI—but don’t fully understand security fundamentals? 



Resources Mentioned:

https://www.proofpoint.com/us/blog/threat-insight/dont-trustconnect-its-a-rat

For more information about Proofpoint, check out our website.

 

Subscribe & Follow:

Stay ahead of emerging threats, and subscribe! Happy hunting!




Episodes: DISCARDED: Tales From the Threat Research Trenches

PodliGet the free Podli app
↓ App